An AI agent can pass every safety check and still leak secrets Elad Meged, a founding engineer at Novee Security, demonstrated that an AI agent can pass every safety check and still leak secrets by running a sequence against three vendors' own repositories in their default configurations. Anthropic's pipeline handed over secrets despite passing safety checks, highlighting a critical gap in AI agent security. A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed … More https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/ The post An AI agent can pass every safety check and still leak secrets https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/ appeared first on Help Net Security https://www.helpnetsecurity.com .